CVE-2022-2421
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
26/10/2022
Last modified:
06/02/2026
Description
Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.
Impact
Base Score 3.x
10.00
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:* | 3.3.3 (excluding) | |
| cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:* | 3.4.0 (including) | 3.4.2 (excluding) |
| cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:* | 4.0.0 (including) | 4.0.5 (excluding) |
| cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:* | 4.1.0 (including) | 4.2.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



